3 ms·
To MITM me they'd need the intermediate or root certs of whatever I am connecting to? I don't see how even pinning the cert would help if the chain is invalid t
by juunpp 3y ago
To MITM me they'd need the intermediate or root certs of whatever I am connecting to? I don't see how even pinning the cert would help if the chain is invalid to begin with.
- wutwutwat 3y agoYes sorry there was a typo in my earlier comment, but that’s what I was saying. If they have a stolen root cert, or are given one, they could produce 100% valid certs and youd never be able to tell they were doing it. I find it hard to believe the root certs of the internet have been kept safe all these years from the intelligence branches of these governments that are at cyber war all the time. I wouldn’t be surprised to one day learn root certificates were willingly given to intelligence branches for “national security” or whatever